Welcome to our UK site – choose your Jurisdiction

Account Information Services and AML: Mutually Exclusive? 

Author: James Borley, Director of Payment Services, Complyport UK

As open banking continues to mature across Europe and the UK, questions regularly arise regarding the Anti-Money Laundering (AML) obligations that should apply to Account Information Service Providers (AISPs). Given that AISPs have access to significant volumes of customer financial data, some commentators have questioned whether they should be subject to the same AML requirements as banks, Payment Institutions and other regulated firms involved in the movement of funds. 

However, both the existing PSD2 framework and the proposed PSD3 package recognise a fundamental distinction between account information services and transactional payment services. Put simply, AISPs provide access to information, not access to money. That distinction has been central to the regulatory treatment of AISPs since open banking was introduced and remains evident in the European Commission’s PSD3 proposals.  

Understanding the AISP Business Model 

Introduced by PSD2, an account information service is an online service that provides consolidated information relating to one or more payment accounts held by a payment service user with one or more Account Servicing Payment Service Providers (ASPSPs), typically banks. The AISP accesses data from existing payment accounts, with the customer’s consent, and presents it in a consolidated format. It does not hold customer funds, operate payment accounts or execute transactions.  

This business model differs fundamentally from that of a bank, Electronic Money Institution or Payment Institution that receives funds, safeguards client money or processes payments. The AISP sits alongside the payment account as a data access provider rather than acting within the payment chain itself.  

That distinction is particularly important from a financial crime perspective. Money laundering risks generally arise where firms are capable of introducing funds into the financial system, moving them between accounts, converting them into different forms of value or facilitating withdrawals. An AISP generally performs none of those activities. Instead, it provides visibility over information that already exists within regulated financial institutions. 

Why AML Obligations Primarily Sit Elsewhere 

The rationale underlying the European AML framework (and as transposed in the UK) has always been that obligations should principally attach to the firms that establish financial relationships and control the movement of funds. 

Banks and payment account providers are therefore responsible for Customer Due Diligence (CDD), sanctions screening, transaction monitoring, ongoing customer reviews and Suspicious Activity Reporting. They are the firms best positioned to assess customer risk and monitor financial activity because they maintain the payment account through which transactions occur. 

In the open banking context, the customer whose data is being accessed has generally already undergone identification and verification by the account servicing institution. The underlying account remains subject to ongoing monitoring by that institution throughout its lifecycle. The AISP is therefore typically accessing information relating to a customer whose identity and activity are already subject to AML controls elsewhere within the financial system.  

From a policy perspective, requiring AISPs to repeat the entirety of those AML processes would often create duplication without materially enhancing the detection or prevention of money laundering. The customer would effectively be subjected to multiple layers of verification even though the AISP neither provides a payment account nor offers an alternative mechanism for moving funds. 

This is one of the primary reasons why regulators have consistently applied a more proportionate approach to AISPs than to firms that actually facilitate payments. 

The Risk Profile of AISPs 

This does not mean that AISPs are entirely irrelevant from an AML perspective. 

Indeed, one of the interesting characteristics of the open banking model is that AISPs may have access to information from multiple accounts and multiple financial institutions simultaneously. In some circumstances, this aggregated view could potentially reveal patterns that may not be visible to any single institution in isolation (‘see it, say it, sorted?’). 

The European Banking Authority (EBA) has recognised this possibility through its sector-specific guidance on money laundering and terrorist financing risk factors for both AISPs and Payment Initiation Service Providers (PISPs). The existence of that guidance demonstrates that regulators do not regard AISPs as entirely devoid of financial crime risk. Rather, they recognise that those risks are materially lower and structurally different from those associated with institutions that hold funds or process transactions. Again, proportionality at work. 

Similarly, some national regulators have considered whether AISPs should undertake elements of transaction monitoring. The Dutch Central Bank, for example, has taken the view that AISPs may have certain monitoring obligations under local AML legislation. However, it has simultaneously emphasised the low inherent money laundering risk presented by AISPs because they neither conduct transactions nor hold customer funds. It also recognises that any controls should be proportionate (that word again) to the nature of the service being provided.  

The broader regulatory theme is therefore one of proportionality rather than exemption. AML considerations may still be relevant, but the nature and extent of any obligations should reflect the comparatively limited role played by AISPs in the movement of money. 

PSD3 Preserves the Status Quo 

The European Commission’s PSD3 proposal, published in June 2023 alongside the proposed Payment Services Regulation (PSR), seeks to strengthen the payments framework by improving fraud prevention, enhancing consumer protection, creating greater supervisory consistency and addressing practical shortcomings identified during the operation of PSD2.  

Importantly though, PSD3 does not seek to change the essential nature of account information services. AISPs remain information-access businesses. They do not become payment account providers, deposit takers or payment executors under the proposed framework. Indeed, one could argus that there is no ‘payment service’ per se but, absent a better fit, PSD2/PSD3 was the best fit for AIS. 

As a result, the underlying logic supporting the differentiated AML treatment of AISPs remains intact. 

The Commission’s review of PSD2 identified challenges relating to open banking performance, fraud prevention, supervisory convergence and the competitive position of non-bank payment providers. However, it did not conclude that AISPs represent a significant money laundering vulnerability requiring a wholesale reassignment of AML responsibilities.  

Consequently, PSD3 broadly preserves the existing allocation of responsibility. The institution maintaining the payment account remains the primary party responsible for customer due diligence and monitoring of transactions taking place through that account.  

This reflects a practical reality: the account servicing institution remains best placed to detect suspicious activity because it has direct control over the underlying account and payment flows. 

The UK Perspective and HM Treasury’s Consultation 

The same principles are increasingly relevant in the United Kingdom as policymakers consider the future of the UK’s payments framework. 

In July 2026, HM Treasury published its consultation on Modernising Payment Services Regulation, setting out proposals to reshape the UK’s payments regime, support Open Banking development and introduce a more agile regulatory framework capable of responding to innovations such as tokenised payments and AI-enabled payment models. Open Banking features prominently within the consultation, with proposals for a stronger long-term framework governing access, standards and infrastructure. 

Whilst the consultation does not propose any fundamental change to the AML treatment of AISPs, it nevertheless presents an opportunity for greater regulatory clarity. 

In particular, the UK authorities could usefully confirm that providers offering pure account information services are not expected to replicate customer due diligence already undertaken by the account servicing institution. Such duplication would increase compliance costs without delivering a corresponding reduction in financial crime risk. 

Similarly, further guidance on the expectations surrounding transaction monitoring would be welcome. AISPs may possess visibility over account information, but they generally lack the ability to stop, reject or control the transactions they observe. Regulatory expectations should therefore recognise the difference between access to data and control over payment activity. 

More broadly, the consultation provides an opportunity to reaffirm an important principle of risk-based regulation: AML obligations should be proportionate to the nature of the activities being undertaken and the risks they create. Where a firm neither holds funds nor facilitates transactions, there is a strong argument that its obligations should differ from those imposed on firms operating at the heart of the payment chain. If this is an area you feel strongly about, the consultation is open for views and comment until 6 October 2026.  

Conclusion 

The treatment of AISPs under PSD2, the proposed PSD3 framework, and existing UK legislation, reflects a simple but important regulatory principle. AML obligations should primarily attach to institutions that establish financial relationships involving customer funds and that control the movement of money. 

AISPs do neither. Their function is informational rather than transactional. Although they may possess valuable insights from aggregated account data and should maintain appropriate financial crime controls, they generally do not present the same money laundering risks as institutions that maintain accounts, execute payments or safeguard funds. 

PSD3 retains this logic, as should the next iteration of payments regulation in the UK. Rather than expanding AML obligations for AISPs, it preserves the established allocation of responsibilities whereby account servicing institutions remain the primary gatekeepers for customer due diligence and transaction monitoring. The UK’s ongoing review of payment services regulation presents an opportunity to provide further clarity on this point, but there appears little appetite on either side of the Channel to depart from a model that is both proportionate and consistent with the fundamental risk profile of account information services. 

How Complyport Can Help 

Complyport supports payment services firms in managing evolving regulatory requirements and maintaining robust compliance frameworks. Our services include: 

  • FCA authorisation for AISPs, PISPs, Payment Institutions and Electronic Money Institutions.  
  • Regulatory compliance advice on payment services and Open Banking.  
  • AML and financial crime frameworks, policies and risk assessments.  
  • Governance and compliance monitoring reviews.  
  • Regulatory change support for PSD3 and UK payment services reforms.  

Whether you are applying for authorisation, reviewing your financial crime framework or preparing for future regulatory developments, Complyport’s experienced consultants can help you build a proportionate and robust compliance framework. 

Contact Complyport today to book a meeting with one of our Subject Matter Experts and discuss how we can support your business. 

Ask ViCA, your Virtual Compliance Assistant. Claim your complimentary 20 queries today! Register here: https://vica.chat 

 

Why Choose Complyport?

Extensive Regulatory Expertise

With over 25 years of experience in the financial services industry, Complyport offers unparalleled expertise in regulatory compliance, ensuring your firm stays ahead of evolving regulations.

Comprehensive Service Offering

From AML audits to risk management and regulatory reporting, Complyport provides a full spectrum of compliance services, allowing you to streamline your compliance processes and focus on your core business activities.

Tailored Compliance Solutions

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Client-Centric Approach

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Senior-Level Guidance

Our team of seasoned professionals, including former regulators and industry experts, leads all engagements, offering deep insights and practical advice to help you manage compliance risks effectively.

Innovative Fintech, Regtech and AI Solutions

Leveraging cutting-edge fintech, regtech and AI tools, Complyport enhances your compliance processes with advanced technology, ensuring accuracy, efficiency, and real-time regulatory updates. Our innovative solutions empower your firm to stay compliant while maximising operational efficiency.

Key Figures

Over 25 Years

Providing Compliance Excellence

Over 1,500

Successful FCA, EU and UAE Authorisations

Over 1,000

Active Firms Receiving
Regulatory Support

8 Lots

FCA/PRA Skilled Person
& Consultancy Panel

Get In Touch